CRPx0 Hidden PowerShell Downloads Stager as WindowsUpdate.log
Detects execution of PowerShell with a hidden window and base64-encoded command arguments that targets the file 'WindowsUpdate.log'. This pattern is associated with the CRPx0 (ClickFix) ransomware, where it attempts to drop or interact with a stager file disguised as a legitimate Windows update log file.
Sigma

